The only place where this would be an issue is the Twtxt Search Engine – But as the GDPR also points out:
Art. 17
The one place the “it propagated and I can’t recall it” problem is legally acknowledged is Art. 17(2), and it explicitly scales to what’s technically feasible:
“…the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure…”
Best-effort, given the technology. A decentralised, append-only, content-addressed feed is the available technology, and its limits are baked into the standard the law applies. Nobody — not the user, not you — is obliged to guarantee every cached copy vanishes.
So just because I enjoy this kind of thing (looking into laws and trying to understand them…):
GDPR is about roles, not ownership
There’s no property right in personal data under GDPR. The whole regime hangs on three roles:
- Data subject — the person the data is about.
- Controller (Art. 4(7)) — “the natural or legal person … which, alone or jointly with others, determines the purposes and means of the processing of personal data.”
- The rights in Arts. 16 and 17 are exercised by a data subject against a controller. They compel a third party to rectify or erase. They are not self-executing duties that a piece of software must expose.
That’s the key. In your architecture, for a user’s own posts about themselves sitting in their own feed on their own device:
- the user is the data subject, and
- the user is also the only person “determining the purposes and means” of that data.
There is no third party controller to compel. The “right to erasure” is a right to make someone else delete — and there is no someone else. It is satisfied the instant the user can change the file. A UI button is a convenience, not a legal requirement. Omitting it removes zero rights, because the data is a plain-text file the user can edit or delete by any means — editor, sed, git, their file manager. Full practical control is retained; nobody is being denied anything by anyone.
LinkedIn Profile Visitor Lists Belong to the People, Says Noyb
A LinkedIn user in the EU is challenging Microsoft’s refusal to provide a full list of profile visitors under GDPR Article 15, arguing that the data should be available for free because LinkedIn processes it and sells a more complete version to Premium users. Privacy group Noyb says the case could set a broader precedent over whether companies can mone … ⌘ Read more
There Is No One Left On Debian’s Data Protection Team
Besides Debian’s aging bug tracker interface, another challenge as the Debian Linux distribution project begins 2026 is that all volunteers have left their Data Protection Team. The Debian Data Protection Team deals with General Data Protection Regulation (GDPR) issues and related data protection/privacy related matters… ⌘ Read more
Europe’s Public Institutions Are Quietly Ditching US Cloud Providers
European public institutions are quietly migrating away from American cloud providers and office software, driven less by policy ambitions in Brussels than by the mundane legal reality that GDPR-mandated risk assessments keep flagging the US CLOUD Act as an unacceptable threat to citizen data.
Austria’s Federal Ministry for Economy, Energ … ⌘ Read more
Still the #DigitalOmnibus :
Tech Policy says “What all of these changes point to is a shift away from empowering people and towards granting discretion to business. What makes the GDPR truly disruptive is that its rights-based approach puts power into the hands of data subjects, of people, and gives them tools to fight back against tech giants, powerful government agencies, and anyone else who uses their data to surveil, track or control them. In a broad sense, shifting towards a risk-based approach to digital regulation tends to allow discretion to powerful actors and creates a maze of loopholes, exemptions, and exceptions that all, ultimately, function as ways for powerful actors to avoid accountability.”
@accessnow.social@accessnow.social says “The new Commission’s decision to prioritize deregulation and securitization above all else is taking the EU in a dangerous direction; one where human rights, once seen as fundamental for the European project, are being sidelined. This will not make people’s lives easier, nor keep them safer. Rather it will transform the EU into a digital dystopia, and ultimately undermine the foundations of European democracy.”
To finish, we have #Macron. #Sovereignty? Nah, what he wants is:
With a straight face, he recommends these anti-sovereingty measures as things that somehow will be good for our tech sovereignty….
At least he puts emphasis on enforcing #DMA, and make sure that hyperscalers comply with it.
He also defends EU-first public procurement, but his examples are SAP and Mistral (and their non-interoperable solutions)…
Finally, he things it is important to speed up AI adoption, going as far as saying that next year instead of a digital sovereignty summit we’ll have an AI summit…
No, not finally! To finish, he wants to “protect the children”! We all know where that one leads…
“TCF” cookie consent popups violate GDPR; OSNews wants to stop using cookie popups too once we get enough Patreons
You may not have heard of the “Transparency & Consent Framework”, but you’ve most likely interacted with it, probably on a daily basis. The TCF is used by 80% of the internet to obtain “consent” from users to collect their data and share it among advertisers – you know, the cookie popups. In a landmark EU ru … ⌘ Read more
Self-hosting my emails again: A few weeks in
A few weeks ago, I moved back to self-hosting my mail server after using Purelymail for three years. The decision wasn’t about cost – it’s actually more expensive to rent a VPS – but about control, security, and data locality. My mails are now hosted in Europe, giving me more confidence in their privacy, and I can configure everything exactly as I want while ensuring compliance with GDPR. ⌘ Read more
Self-hosting my emails again
After three years with Purelymail, I’m back at self-hosting my mail server. Not because it’s cheaper (it’s actually much pricier to pay for a VPS), but because my mails are now hosted in Europe (who knows what happens next in the USA), I have more control to configure things how I want, and I can comply with GDPR. ⌘ Read more
@Prologic@twtxt.net Looking at Threema because it is European with servers in Switzerland and it has GDPR conformity, among some other reasons.
83(4) GDPR sets forth fines of up to 10 million euros, or, in the case of an undertaking, up to 2% of its entire global turnover of the preceding fiscal year, whichever is higher.
Though I suppose it has to be the greater of the two. But I don’t even have one euro to start with.
@falsifian@www.falsifian.org The GDPR does not apply to the processing of data for a purely personal or household activity that is not connected to a professional or commercial activity.
@prologic@twtxt.net I have no specifics, only hopes. (I have seen some articles explaining the GDPR doesn’t apply to a “purely personal or household activity” but I don’t really know what that means.)
I don’t know if it’s worth giving much thought to the issue unless either you expect to get big enough for the GDPR to matter a lot (I imagine making money is a prerequisite) or someone specifically brings it up. Unless you enjoy thinking through this sort of thing, of course.
@prologic@twtxt.net Do you have a link to some past discussion?
Would the GDPR would apply to a one-person client like jenny? I seriously hope not. If someone asks me to delete an email they sent me, I don’t think I have to honour that request, no matter how European they are.
I am really bothered by the idea that someone could force me to delete my private, personal record of my interactions with them. Would I have to delete my journal entries about them too if they asked?
Maybe a public-facing client like yarnd needs to consider this, but that also bothers me. I was actually thinking about making an Internet Archive style twtxt archiver, letting you explore past twts, including long-dead feeds, see edit histories, deleted twts, etc.
RT by @mind_booster: ❗Breaking: Meta Tracking Tools unlawful
In a groundbreaking decision in one of noybs 101 complaints, the Austrian Data Protection Authority decided that the use of Facebook’s tracking pixel directly violates the GDPR: https://noyb.eu/en/austrian-dsb-meta-tracking-tools-illegal?mtc=tw
❗Breaking: Meta Tracking Tools unlawful
In a groundbreaking decision in one of noybs 101 complaints, the Austrian Data Protection Authority decided that the use of Facebook’s tracking pixel directly violates th … ⌘ Read more
When you submit a GDPR request to American Express (Germany), you get an “Encrypted Mail” (for which you have to log in again somewhere and set a password), which then contains two PDFs, one of which is full of screenshots of mainframe terminals. ⌘ Read more
Suggestion for the next #GDPR iteration: No landing pages allowed. Content must be served on the first request.
The easiest path to GDPR compliance: switch to a completely static website with no javascript, CGI, or CSS, and rotate the logs daily.
GDPR Hysteria · Jacques Mattheij https://jacquesmattheij.com/gdpr-hysteria
Doc Searls Weblog · GDPR will pop the adtech bubble https://blogs.harvard.edu/doc/2018/05/12/gdpr/